GregLab | Exam Prep

Design security solutions for infrastructure

Network Security and Security Service Edge

Core

Evaluate segmented network designs and identity-centric SSE patterns for internet, Microsoft-service, and private-application traffic across users, branches, and tenants.

Aligned to SC-100 skills measured as of October 21, 2026; candidates testing earlier should review the transition note in the lane overview.

Why this matters

Network location alone is weak evidence of trust. Modern designs combine segmentation, private connectivity, inspected egress, identity-aware access, device and risk signals, and explicit cross-tenant controls at the traffic path that owns enforcement.

Must Know

  • Evaluate network architecture for segmentation, ingress and egress control, private connectivity, DNS, route intent, inspection placement, resilience, logging, and operational ownership.
  • Microsoft Entra Internet Access for all apps provides an identity-centric secure web gateway for internet and SaaS traffic, including web content filtering and security profiles.
  • The Microsoft traffic profile secures supported Microsoft service traffic and can support compliant-network enforcement and Universal Tenant Restrictions for cross-tenant control.
  • Microsoft Entra Private Access provides identity-aware access to defined private applications through connectors, avoiding broad network-level access granted by traditional VPN designs.
  • Traffic forwarding profiles determine which Microsoft, private, or internet flows enter Global Secure Access; forwarding alone does not authorize access to every destination.
  • SSE complements rather than automatically replaces workload network controls, service firewalls, private endpoints, and east-west segmentation.

Compare and Distinguish

  • Internet Access protects public internet and SaaS traffic; the Microsoft traffic profile specializes in supported Microsoft services; Private Access brokers defined private resources.
  • ZTNA grants application-specific access based on identity context, while a traditional VPN commonly extends broader network reachability.

Scenario examples

  • Scenario: Remote users need only two internal applications and access must depend on device compliance. Think: publish those private resources through Entra Private Access and enforce identity-aware application access.
  • Scenario: Users must reach corporate Microsoft services but not personal or unapproved tenants. Think: use the Microsoft traffic profile with Conditional Access and Universal Tenant Restrictions.

Exam traps

  • Enabling a forwarding profile captures traffic but does not create destination definitions, assignments, or application authorization.
  • Moving user egress to SSE does not remove the need to protect public workload origins and internal east-west paths.

Key takeaways

  • Internet, Microsoft-service, and private-resource traffic require different forwarding profiles.
  • A forwarding profile captures traffic; destination definition and access policy authorize it.
  • SSE protects user and branch paths, not Azure workload east-west traffic by implication.
How it works
  • Clients or remote networks forward selected traffic to the service edge, which evaluates profiles and associated identity-aware policies.
  • Private Network Connectors broker outbound connections to configured private resources so inbound exposure is not required.
Objects and administrative surfaces
  • Virtual networks, subnets, routes, firewalls, WAFs, private endpoints, DNS, DDoS controls, flow logs, and central inspection hubs.
  • Global Secure Access clients and connectors, traffic profiles, enterprise applications, Quick Access definitions, security profiles, Conditional Access, and tenant restrictions.
When to use it
  • Use SSE when user and branch access policy must follow identity and device context beyond a corporate perimeter.
Security and governance implications
  • Govern destination definitions, TLS inspection policy, privacy, exception handling, tenant restrictions, and connector resilience before broad rollout.
Troubleshooting signals
  • If traffic bypasses controls, verify client health, profile assignment, acquisition rules, route conflicts, and forwarding precedence.
  • If a private app is unreachable, inspect its Quick Access or enterprise-app definition, connector group, assignments, DNS, and backend reachability.
More detail
  • Evaluate conventional network design against explicit security requirements.
  • Choose Internet Access modes for public and Microsoft traffic.
  • Use Private Access for application-specific private connectivity.

Ready for the quiz?

  • Which profile handles a private line-of-business application?
  • What prevents data transfer to an unapproved Microsoft tenant?
  • Which controls remain inside a workload after adopting SSE?

Related objectives

  • D3.4.S1 — Evaluate network designs to align with security requirements and best practices
  • D3.4.S2 — Evaluate solutions that use Microsoft Entra Internet Access as a secure web gateway
  • D3.4.S3 — Evaluate solutions that use Microsoft Entra Internet Access for Microsoft Services, including cross-tenant configurations
  • D3.4.S4 — Evaluate solutions that use Microsoft Entra Private Access

Learn more

Free Microsoft Certified: Cybersecurity Architect Expert prep

Build focused SC-100 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Read Topics Build a quiz

Exam Weights

Exam snapshot

SC-100 at a glance

Level
Expert
Duration
No SC-100-specific assessment duration published on the reviewed official pages
Questions
No fixed live question count published
Formats
No guaranteed question-type mix; the proctored exam may include interactive components
Scoring
Scaled score; 700 minimum passing score

Quiz builder

Choose your practice set

Mode

Exam fidelity: Microsoft does not publish a fixed live question count or guarantee a question-type mix for SC-100. This lane contains multiple-choice and multiple-response exam-style practice aligned to the October 21, 2026 blueprint. Practice percentages do not reproduce Microsoft's scaled scoring, and difficulty labels describe this site's Expert-level cybersecurity architecture complexity rather than a Microsoft-published question rating.

Reference

SC-100 topics and reference map

Study links

SC-100 resources